Form template for completing a Data Protection Impact Assessment (DPIA).
The requirement to complete a Data Protection Impact Assessment (DPIA) was introduced with the General Data Protection Regulation (Art. 35 of the GDPR). This refers to the obligation of the data controller to conduct an impact assessment and to document it before starting the intended data processing.
This form can be completed at the start of any major project involving the use of personal data, or when making a significant change to an existing process where personal data is being processed.
Document is structured as follows:
- Assessment of the need for a DPIA
- Describe the Processing
- Consultation Process
- Assessment of Necessity and Proportionality
- Assessment of risk and controls to mitigate risk
There is also a risk assessment featured as part of this form.
[Information Classification: Business Use]